VORANT. Threat Intelligence Sign in Get the full feed

Trend Micro Apex One RCE flaws exploited

high vulnerability technology

Two command injection vulnerabilities in Trend Micro Apex One management console are being actively exploited to achieve remote code execution.

Japan's IPA issued an alert regarding two command injection vulnerabilities (CVE-2025-54948 and CVE-2025-54987) affecting Trend Micro's Apex One, Apex One SaaS, and Standard Endpoint Protection products. The flaws exist in the management console and allow remote code execution, posing a significant risk given these are widely deployed endpoint security products.

As of the August 19 update, IPA confirmed the vulnerabilities are already being actively exploited in the wild, with potential for expanding damage. Trend Micro has released fixes and, for Apex One specifically, a mitigation tool called "FixTool_Aug2025" as an interim measure. Apex One SaaS and Standard Endpoint Protection users reportedly do not need to take independent action, suggesting those variants are managed/patched server-side by the vendor. IPA urges organizations running the on-premises Apex One product to apply patches urgently given confirmed exploitation.

Mentioned in this report

Vulnerabilities CVE-2025-54948KEVCVE-2025-54987

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250807.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free